legal / privacy policy
We collect nothing. Really.
last updated · February 1, 2026 · applies to the whole service
1. Who we are
TempMail ("we", "us") operates the public temporary Gmail OTP receiver, the tool pages, and the blog found on this domain. This policy explains the very small amount of data our systems touch — and how little of it is "yours".
2. What we collect
- Anonymous analytics. A SHA-256 hash of your IP address, a country tag, and the page you visited. Hashes cannot be reversed into IPs and are used only for aggregate visitor counts.
- Public email content. The emails that arrive in the public Gmail inboxes — which are public by design and deleted within 5 minutes.
- Contact form messages. Only what you type into the contact form, delivered to our mail account and deleted from the database immediately.
- Admin credentials. A bcrypt-hashed administrator password and encrypted Gmail app passwords (AES-256-GCM). Never plaintext, never exposed via any API.
3. What we never collect
We do not require an account, name, phone number, or personal email. We do not use tracking pixels or cross-site fingerprinting. We do not sell, rent, or share any data with data brokers, marketers, or third parties.
4. The 5-minute purge (GDPR Art. 5 & 17)
All incoming mail is automatically and permanently deleted — from Google’s servers via IMAP EXPUNGE and from our database — within 5 minutes of receipt. There is no backup, archive, or recovery path. This satisfies the GDPR principles of storage limitation and data minimization and your right to erasure by design.
5. Cookies & local storage
We set a single HttpOnly session cookie for the admin panel and use localStorage for your light/dark theme preference. No third-party cookies, no advertising cookies set by us.
6. Your rights (GDPR / CCPA)
Since we store no personal data about visitors, there is effectively nothing to access, correct, or delete. If you believe otherwise, email the contact address with the subject "PRIVACY REQUEST" and we will respond within 30 days. California residents: this service does not "sell or share" personal information within the meaning of the CCPA because it does not collect any.
7. Children & sensitive data
The service is not directed at children under 13. Never use a public inbox to receive health, financial, or identity data — public mail is readable by anyone for up to 5 minutes.
8. Contact
Questions about this policy? Use the contact page or email the address listed there.